EvilTokens Exploits Railway PaaS for M365 Attacks
Score: 9/10

EvilTokens Exploits Railway PaaS for M365 Attacks

The EvilTokens Phishing-as-a-Service platform is weaponizing Railway.com PaaS infrastructure to conduct large-scale OAuth token replay and device code phishing campaigns against Microsoft 365 environments.

Executive Summary

Security researchers have identified an active, accelerating campaign attributed to the EvilTokens Phishing-as-a-Service (PhaaS) platform, operated by the NOIRLEGACY GROUP. The campaign targets Microsoft 365 identities across over 340 organizations globally, including those in the US, Canada, and Germany. The primary methodology involves weaponizing Railway.com, a Platform-as-a-Service (PaaS) provider, to host token-replay engines and credential-harvesting infrastructure. This approach leverages Railway's legitimate IP reputation to bypass risk-based scoring and automated email filters.

The attack is technically mature, utilizing AI-driven lures and sophisticated delivery chains that include multi-hop redirects and the abuse of email security vendor URL rewriters (e.g., Cisco, Trend Micro, Mimecast). By exploiting the OAuth device authorization flow, attackers obtain persistent tokens that remain valid even after password resets and effectively bypass Multi-Factor Authentication (MFA). Immediate defensive actions include blocking Railway CIDR blocks and hunting for specific behavioral Indicators of Compromise (IoCs) within identity logs.

Key Details

Threat Name

EvilTokens

Affects

—

Adversary

EvilTokens Other Adversaries and Aliases: NOIRLEGACY GROUP

Malware/Tools

EvilTokens

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance9
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources